Pranith-Jain/Pranith-Jain
GitHub: Pranith-Jain/Pranith-Jain
安全分析师个人主页仓库,集中托管部署于 Cloudflare Workers 的 DFIR 工具包与自更新威胁情报平台的链接、项目索引及技术履历。
Stars: 0 | Forks: 0
```
██████╗ ██████╗ █████╗ ███╗ ██╗██╗████████╗██╗ ██╗
██╔══██╗██╔══██╗██╔══██╗████╗ ██║██║╚══██╔══╝██║ ██║
██████╔╝██████╔╝███████║██╔██╗ ██║██║ ██║ ███████║
██╔═══╝ ██╔══██╗██╔══██║██║╚██╗██║██║ ██║ ██╔══██║
██║ ██║ ██║██║ ██║██║ ╚████║██║ ██║ ██║ ██║
╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝╚═╝ ╚═╝ ╚═╝ ╚═╝
```
### 安全分析师与检测工程师 · 威胁情报 · 邮件防御 · 边缘原生工具
[](https://www.linkedin.com/in/pranithjain/)
[](https://pranithjain.qzz.io)
[](https://pranithjain.qzz.io/dfir)
[](https://pranithjain.qzz.io/threatintel)
[](mailto:hello@pranithjain.qzz.io)
[](https://x.com/Npj8448)

## whoami
```
name: Pranith Jain
role: Security Analyst & Detection Engineer
company: Qubit Capital
location: Bengaluru, India
focus:
- Threat Intelligence & IOC Analysis
- Detection Engineering & Edge-native Security Tooling
- Email Security & BEC Investigations
- Phishing Triage & Malware Detection
- Security Automation & AI Workflows
- DMARC Enforcement & Domain Abuse Monitoring
currently_building:
- DFIR toolkit (70+ MCP tools) + self-updating Threat Intel platform on Cloudflare Workers
- Autonomous case-study blog: discover → AI generate → anti-slop QA gate → publish
- Hourly cross-source IOC correlation + in-browser Detection Lab + universal rule converter
expanding_into:
- AI Security (prompt injection, MCP, agent attack surface)
- Non-Human Identity (NHI) governance
open_to: Security Engineering · Detection Engineering · AI Security · Threat Intelligence
```
## 我的工作方向
我从事大规模的威胁情报和邮件防御工作,并开发能提升工作效率的工具。
- **威胁情报** — 勒索软件泄露网站与谈判跟踪、跨来源 IOC 关联、攻击者 / CVE / KEV 扩展追踪、MITRE ATT&CK 映射、暗网与论坛情报
- **检测工程** — 编写 Sigma / YARA / KQL / SPL / Lucene / EQL / DLP 规则,以及一个支持它们之间双向转换的通用转换器;在浏览器内运行的检测实验室,每小时针对实时 IOC 数据流进行评估
- **邮件安全** — SPF, DKIM, DMARC, BIMI, MTA-STS 强制执行;BEC 调查;网络钓鱼分类处理;域名滥用下架
- **安全自动化** — n8n 与 MCP pipeline,利用 Claude Code 进行 AI 驱动的富化与分类,以及 SOC playbook
- **AI 与云安全** — prompt 注入测试,MCP 审计,agent 攻击面映射;IAM / Zero Trust 态势;NHI 治理
## 精选项目:DFIR 工具包 + 威胁情报平台
只需一次 Cloudflare Workers 部署。包含 **70+ 分析师工具** 和一个实时自更新的 CTI 展示面 — 无需注册,无需密钥,边缘缓存且在边缘节点免费使用。
### `/dfir` — DFIR 工具包
涵盖分类、OSINT、邮件安全、检测工程、AI 安全、数据安全、云端、API 等 70+ 交互式工具。亮点包括:
- **IOC 与哈希检查器** — 并行流式传输 24 个提供商的 IP、域名、URL、哈希数据
- **检测引擎与通用规则转换器** — 通过统一的 RuleIR 实现 Sigma ↔ KQL ↔ SPL ↔ Lucene ↔ EQL ↔ YARA ↔ DLP 互转
- **邮件防御 / BEC 评分** — SPF / DKIM / DMARC / BIMI / MTA-STS / TLS-RPT 评分
- **AI 安全工具** — prompt 注入红队测试、MCP 审计、agent 攻击面映射、MITRE ATLAS
- **数据安全** — 基于 Luhn / IBAN / Verhoeff 算法验证的敏感数据检测、分类及隐私中心
### `/threatintel` — 威胁情报平台
20+ 每小时刷新的实时 CTI 展示面:
- **勒索软件泄露网站与谈判跟踪** — 汇聚 Ransomlook、ransomware.live PRO 和 MyThreatIntel
- **跨来源 IOC 关联** — 基于 18 个情报源进行共识评分;实时 IOC 数据流
- **攻击者时间线 + MITRE ATT&CK 组织/TTP 扩展追踪**
- **自动生成的日报与周报情报简报** — 数据支撑,于 UTC 时间 00:05 / 00:15 发布
- **自动化案例研究博客** — 发现 → AI 生成 → 反垃圾 QA 把关 → 发布;每小时进行 Telegram 摘要广播
专为适配 **Cloudflare Workers 免费层**而设计:提供商结果缓存至 Cache API(而非 KV),单次 cron 锁定,基于请求的 nonce CSP,以及防范 SSRF 的出站请求。
**技术栈:**






## 技术栈
### 安全运营





### 邮件安全




### 自动化、AI 与边缘计算






### 威胁情报与 OSINT




### 云安全



### 脚本编写



## 仓库内容
### 旗舰项目
- [**Pranith-Jain.github.io**](https://github.com/Pranith-Jain/Pranith-Jain.github.io) — 个人作品集 + **DFIR 工具包 + 威胁情报平台**(部署于 [pranithjain.qzz.io](https://pranithjain.qzz.io))
- [**dfir-mcp-server**](https://github.com/Pranith-Jain/dfir-mcp-server) — 为 AI agent 提供 20+ DFIR 与威胁情报工具的 MCP server,基于 Cloudflare Workers 构建
- [**dfir-threat-intel-agent**](https://github.com/Pranith-Jain/dfir-threat-intel-agent) — 自主多步 LLM 驱动的调查 agent(包含 计划→行动→观察 循环,30+ 情报工具,结构化报告综合)
- [**DFIR-PLATFORM**](https://github.com/Pranith-Jain/DFIR-PLATFORM) — 工具包的设计轨迹与原型
- [**cti-platform**](https://github.com/Pranith-Jain/cti-platform) — 实时勒索软件跟踪、跨来源 IOC 关联、威胁攻击者时间线、情报简报
### CLI 与工具
- [**dfir-cli**](https://github.com/Pranith-Jain/dfir-cli) — DFIR 命令行工具:IOC 提取、编码、文件分析、PE 分类
- [**cti-cli**](https://github.com/Pranith-Jain/cti-cli) — 命令行威胁情报:AI 副驾驶、IOC 检查器、13+ 情报源
- [**cti-stix-connector**](https://github.com/Pranith-Jain/cti-stix-connector) — 容器化的 Python 命令行工具,用于摄取 JSON 活动 Campaign 和 CSV IOC 源,并输出 STIX 2.1 bundle
- [**cti-ai-skills**](https://github.com/Pranith-Jain/cti-ai-skills) — 用于 CTI 工作流的 AI 技能
### 其他
- [**AI-Agent-Portfolio**](https://github.com/Pranith-Jain/AI-Agent-Portfolio) — MindStudio AI Agent 实验
- [**Secure-Patient-Data-Platform-on-Google-Cloud-Capstone-**](https://github.com/Pranith-Jain/Secure-Patient-Data-Platform-on-Google-Cloud-Capstone-) — 基于 Zero Trust 且符合 HIPAA 标准的 GCP 毕业项目(评分 A,93/100)
## 认证证书
| 认证名称 | 颁发机构 | 年份 |
|---|---|---|
| Proofpoint Certified AI Agent Security Specialist | Proofpoint | 2026 |
| SOC Summit 2026 | SOC Summit | 2026 |
| Antisyphon Training | Antisyphon | 2026 |
| Data Loss Prevention (DLP) Survival Guide | Fortra | 2026 |
| Social Media Intelligence (SOCMINT) | CyberSudo | Mar 2026 |
| Certified AI Security Expert | Virtual Cyber Labs | Mar 2026 |
| Proofpoint AI Email Security Specialist | Proofpoint | 2025 |
| Effective AI for Practical SecOps Workflows | ISC2 | 2025 |
| Mastering Cyber Threat Intelligence for SOC Analysts | MCSI | 2025 |
| DSPM Fundamentals | Fortra | 2025 |
| Certified Cyber Criminologist | Virtual Cyber Labs | 2025 |
| Google Cloud Cybersecurity Certificate | Google | 2025 |
| Multi-Cloud Blue Team Analyst (MCBTA) | CyberWarFare Labs | 2025 |
## GitHub 统计